ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1518.001×

27 examples

TechniqueUsed byProcedure example
T1518.001
Security Software Discovery
GroupAPT38

APT38 has identified security software, configurations, defensive tools, and sensors installed on a compromised system.

T1518.001
Security Software Discovery
GroupBlackByte

BlackByte enumerated installed security products during operations.

T1518.001
Security Software Discovery
GroupSideCopy

SideCopy uses a loader DLL file to collect AV product names from an infected host.

T1518.001
Security Software Discovery
GroupKimsuky

Kimsuky has checked for the presence of antivirus software with powershell Get-CimInstance -Namespace root/securityCenter2 – classname antivirusproduct. Kimsuky has also obtained details on antivirus software through WMI queries using `Win32_OperatingSystem` and `SecurityCenter2.AntiVirusProduct`. Kimsuky has also checked the status of Windows Defender through the use `cmd /s sc query WinDefend`.

T1518.001
Security Software Discovery
GroupPatchwork

Patchwork scanned the “Program Files” directories for a directory with the string “Total Security” (the installation path of the “360 Total Security” antivirus tool).

T1518.001
Security Software Discovery
GroupMuddyWater

MuddyWater has used malware to check running processes against a hard-coded list of security tools often used by malware researchers.

T1518.001
Security Software Discovery
GroupNaikon

Naikon uses commands such as netsh advfirewall firewall to discover local firewall settings.

T1518.001
Security Software Discovery
GroupGamaredon Group

Gamaredon Group has used PowerShell scripts to identify security software on the victim machine.

T1518.001
Security Software Discovery
GroupTeamTNT

TeamTNT has searched for security products on infected machines.

T1518.001
Security Software Discovery
GroupSidewinder

Sidewinder has used the Windows service winmgmts:\\.\root\SecurityCenter2 to check installed antivirus products.

T1518.001
Security Software Discovery
GroupRocke

Rocke used scripts which detected and uninstalled antivirus software.

T1518.001
Security Software Discovery
GroupTA2541

TA2541 has used tools to search victim systems for security products such as antivirus and firewall software.

T1518.001
Security Software Discovery
GroupTropic Trooper

Tropic Trooper can search for anti-virus software running on the system.

T1518.001
Security Software Discovery
GroupAquatic Panda

Aquatic Panda has attempted to discover third party endpoint detection and response (EDR) tools on compromised systems.

T1518.001
Security Software Discovery
GroupThe White Company

The White Company has checked for specific antivirus products on the target’s computer, including Kaspersky, Quick Heal, AVG, BitDefender, Avira, Sophos, Avast!, and ESET.

T1518.001
Security Software Discovery
GroupTurla

Turla has obtained information on security software, including security logging information that may indicate whether their malware has been detected.

T1518.001
Security Software Discovery
GroupStorm-0501

Storm-0501 has detected endpoint security solutions using `sc query sense` and `sc query windefend`.

T1518.001
Security Software Discovery
GroupMedusa Group

Medusa Group has detected security solutions for termination or deletion within the victim device using hard-coded lists of strings containing security product executables.

T1518.001
Security Software Discovery
GroupDarkhotel

Darkhotel has searched for anti-malware strings and anti-virus processes running on the system.

T1518.001
Security Software Discovery
GroupWindshift

Windshift has used malware to identify installed AV and commonly used forensic and malware analysis tools.

T1518.001
Security Software Discovery
GroupToddyCat

ToddyCat can determine is Kaspersky software is running on an endpoint by running `cmd /c wmic process where name="avp.exe"`.

T1518.001
Security Software Discovery
GroupMalteiro

Malteiro collects the installed antivirus on the victim machine.

T1518.001
Security Software Discovery
GroupAPT42

APT42 has used Windows Management Instrumentation (WMI) to check for anti-virus products.

T1518.001
Security Software Discovery
GroupCobalt Group

Cobalt Group used a JavaScript backdoor that is capable of collecting a list of the security solutions installed on the victim's machine.

T1518.001
Security Software Discovery
GroupWizard Spider

Wizard Spider has used WMI to identify anti-virus products installed on a victim's machine.

T1518.001
Security Software Discovery
GroupPlay

Play has used the information-stealing tool Grixba to scan for anti-virus software.

T1518.001
Security Software Discovery
GroupFIN8

FIN8 has used Registry keys to detect and avoid executing in potential sandboxes.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.